Build on the supported package contract
Use @absolutejs/agent-exchange-broker through its supported public entry points.
@absolutejs/agent-exchange-brokerv0.3.0betaAITenant-fenced, one-time token-confined broker contracts for AbsoluteJS Agent Exchange.
bun add @absolutejs/agent-exchange-brokerExecutes one passkey-approved, purpose-bound Agent Exchange operation while confining an upstream bearer access token to deterministic provider code. The token is never returned to either agent, placed in the request, or serialized in the receipt.
This assurance is deliberately weaker than a DPoP or mTLS sender-constrained access token: compromise of the broker process can expose a live bearer token. Use tenant-isolated encrypted credential storage, an atomic durable store, restricted egress, short expiries, revocation, and aggressive rate limits.
The broker also accepts standing-mandate + token-confined-broker + purpose-bound after the host has cryptographically authorized and atomically consumed the request's separate mandateId. The broker does not verify mandates itself.
Outcomes
Use @absolutejs/agent-exchange-broker through its supported public entry points.
Hardening checklist
Follow in order
Supported entry points declared by this package manifest.
Scripts declared by this package manifest.
Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.